vendor:
OpenHelpDesk
by:
LSO
7.5
CVSS
HIGH
PHP Code Execution
78
CWE
Product Name: OpenHelpDesk
Affected Version From: 1.0.100
Affected Version To: 1.0.100
Patch Exists: NO
Related CWE: N/A
CPE: a:openhelpdesk:openhelpdesk:1.0.100
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2008
OpenHelpDesk eval (previously unpublished)
OpenHelpDesk version 1.0.100 is vulnerable to a php code execution vulnerability due to improper use of eval(). The php.ini register_globals directive is *not* required to be on to exploit this vulnerability. There is no known public exploit for this vulnerability.
Mitigation:
Ensure that the application is not vulnerable to code injection attacks.